Once again, sorry for the late reply…
I ran the scan as instructed; only OTL.txt was created when it finished running. I'll post that here; if I find Extras.txt, I'll add that in a second post.
Results from OTL.txt:
OTL logfile created on: 2/11/2013 2:27:21 PM - Run 2
OTL by OldTimer - Version 3.2.65.1 Folder = C:\Documents and Settings\Family\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.88 Mb Total Physical Memory | 612.58 Mb Available Physical Memory | 60.42% Memory free
2.39 Gb Paging File | 2.07 Gb Available in Paging File | 86.79% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.05 Gb Total Space | 109.65 Gb Free Space | 77.19% Space Free | Partition Type: NTFS
Computer Name: SHUSTERSWEENEY | User Name: Family | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/09/22 16:56:46 | 000,600,576 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Family\My Documents\Downloads\OTL.exe
PRC - [2012/09/08 09:19:28 | 000,161,768 | —- | M] (Oracle Corporation) – C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/09/08 09:19:26 | 000,174,056 | —- | M] (Oracle Corporation) – C:\Program Files\Java\jre7\bin\javaw.exe
PRC - [2012/09/08 09:19:25 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\system32\java.exe
PRC - [2012/07/14 08:59:32 | 000,497,320 | —- | M] (Check Point Software Technologies) – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
PRC - [2012/07/03 08:04:58 | 000,507,312 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2009/02/05 10:14:56 | 000,237,568 | —- | M] (Acer Incorporated) – C:\Program Files\Acer\Acer VCM\RS_Service.exe
PRC - [2008/12/30 02:09:54 | 000,875,016 | —- | M] (Dritek System Inc.) – C:\Program Files\Launch Manager\LManager.exe
PRC - [2008/11/13 14:43:49 | 000,204,800 | —- | M] () – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
PRC - [2008/11/13 10:09:44 | 000,065,536 | —- | M] (Prolific) – C:\Program Files\Prolific\EZ-DUB Finder\OneBtn.exe
PRC - [2008/10/14 13:15:08 | 000,032,768 | —- | M] () – C:\WINDOWS\WebCam\M3000\M3000Mnt.exe
PRC - [2008/10/02 22:18:36 | 000,294,544 | —- | M] (Carbonite, Inc.) – C:\Program Files\Carbonite\CarbonitePreinstaller.exe
PRC - [2008/07/10 08:23:26 | 002,049,320 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
PRC - [2008/07/10 08:23:26 | 000,053,032 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
PRC - [2008/07/10 08:23:16 | 001,442,088 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
PRC - [2008/07/10 08:23:04 | 001,083,176 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\InCD.exe
PRC - [2008/04/15 19:54:42 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/14 07:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/09/13 20:50:00 | 001,603,152 | —- | M] (CANON INC.) – C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2007/04/13 10:49:00 | 000,101,528 | —- | M] () – C:\Program Files\Canon\IJPLM\ijplmsvc.exe
PRC - [2006/01/25 05:45:50 | 000,053,248 | —- | M] (Realtek Semiconductor Corp.) – C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
========== Modules (No Company Name) ==========
MOD - [2008/11/13 14:43:49 | 000,204,800 | —- | M] () – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
MOD - [2008/11/13 14:43:49 | 000,081,920 | —- | M] () – C:\Program Files\Linksys\Linksys Updater\lib\wrapper.dll
MOD - [2008/10/14 13:15:08 | 000,032,768 | —- | M] () – C:\WINDOWS\WebCam\M3000\M3000Mnt.exe
MOD - [2007/04/13 10:49:00 | 000,101,528 | —- | M] () – C:\Program Files\Canon\IJPLM\ijplmsvc.exe
MOD - [2003/06/07 00:30:08 | 000,057,344 | —- | M] () – C:\Program Files\Launch Manager\PowerUtl.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)
SRV - File not found [Auto | Stopped] – C:\DOCUME~1\Family\LOCALS~1\Temp\004659~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini – (0046591276984199mcinstcleanup)
SRV - [2012/10/05 10:08:42 | 000,109,064 | —- | M] (Wajam) [Auto | Stopped] – C:\Program Files\Wajam\Updater\WajamUpdater.exe – (WajamUpdater)
SRV - [2012/09/08 09:19:28 | 000,161,768 | —- | M] (Oracle Corporation) [Auto | Running] – C:\Program Files\Java\jre7\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2012/08/21 04:12:25 | 000,044,808 | —- | M] (AVAST Software) [Auto | Stopped] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV - [2012/07/30 11:31:04 | 002,445,880 | —- | M] (Check Point Software Technologies LTD) [Auto | Stopped] – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe – (vsmon)
SRV - [2012/07/14 08:59:32 | 000,497,320 | —- | M] (Check Point Software Technologies) [Auto | Running] – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe – (IswSvc)
SRV - [2012/06/05 14:17:44 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2010/03/21 14:41:00 | 003,532,120 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\WINDOWS\system32\GameMon.des – (npggsvc)
SRV - [2009/02/05 10:14:56 | 000,237,568 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Acer\Acer VCM\RS_Service.exe – (RS_Service)
SRV - [2008/12/12 18:06:40 | 000,642,856 | —- | M] (Cisco Systems, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe – (nmservice)
SRV - [2008/11/13 14:43:49 | 000,204,800 | —- | M] () [Auto | Running] – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe – (LinksysUpdater)
SRV - [2008/07/10 08:23:26 | 000,053,032 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe – (NeroRegInCDSrv)
SRV - [2008/07/10 08:23:16 | 001,442,088 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe – (InCDsrv)
SRV - [2008/04/15 19:54:42 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON)
SRV - [2007/04/13 10:49:00 | 000,101,528 | —- | M] () [Auto | Running] – C:\Program Files\Canon\IJPLM\ijplmsvc.exe – (IJPLMSVC)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\Rts5161ccid.sys – (USBCCID)
DRV - File not found [Kernel | System | Stopped] – C:\Program Files\SUPERAntiSpyware\SABKUTIL.sys – (SABKUTIL)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\Rts516xIR.sys – (Rts516xIR)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] – c:\acernb\int15.sys – (int15.sys)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\Family\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2012/09/27 11:59:49 | 000,040,776 | —- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mbamswissarmy.sys – (MBAMSwissArmy)
DRV - [2012/08/21 04:13:15 | 000,729,752 | —- | M] (AVAST Software) [File_System | System | Running] – C:\WINDOWS\System32\drivers\aswSnx.sys – (aswSnx)
DRV - [2012/08/21 04:13:15 | 000,355,632 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswSP.sys – (aswSP)
DRV - [2012/08/21 04:13:15 | 000,054,232 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswTdi.sys – (aswTdi)
DRV - [2012/08/21 04:13:14 | 000,097,608 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\WINDOWS\System32\drivers\aswmon2.sys – (aswMon2)
DRV - [2012/08/21 04:13:14 | 000,035,928 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswRdr.sys – (aswRdr)
DRV - [2012/08/21 04:13:13 | 000,025,256 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aavmker4.sys – (Aavmker4)
DRV - [2012/08/21 04:13:13 | 000,021,256 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\WINDOWS\System32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2012/07/30 10:59:48 | 000,526,640 | —- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] – C:\WINDOWS\system32\vsdatant.sys – (Vsdatant)
DRV - [2012/07/14 08:59:44 | 000,027,056 | —- | M] (Check Point Software Technologies) [Kernel | Auto | Running] – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys – (ISWKL)
DRV - [2010/05/10 13:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 13:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/03/02 00:03:46 | 000,038,912 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l1c51x86.sys – (L1c)
DRV - [2009/02/25 22:17:52 | 001,344,224 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\athw.sys – (AR5416)
DRV - [2009/02/24 03:49:44 | 005,032,448 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService)
DRV - [2009/02/03 01:42:30 | 000,162,816 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/01/02 20:33:54 | 000,145,408 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\M3000KNT.sys – (M3000Srv)
DRV - [2008/12/12 18:05:20 | 000,025,264 | —- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\purendis.sys – (purendis)
DRV - [2008/12/12 18:05:18 | 000,023,984 | —- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\pnarp.sys – (pnarp)
DRV - [2008/11/26 18:13:00 | 000,009,984 | —- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\plturbo.sys – (PLTurbo)
DRV - [2008/08/05 07:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/07/10 08:23:14 | 000,040,488 | —- | M] (Nero AG) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\InCDRm.sys – (incdrm)
DRV - [2008/07/10 08:23:14 | 000,038,952 | —- | M] (Nero AG) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\InCDPass.sys – (InCDPass)
DRV - [2008/07/10 08:23:14 | 000,018,088 | —- | M] (Nero AG) [Recognizer | System | Unknown] – C:\WINDOWS\system32\drivers\InCDrec.sys – (InCDRec)
DRV - [2008/07/10 08:23:04 | 000,128,424 | —- | M] (Nero AG) [File_System | Disabled | Running] – C:\WINDOWS\system32\drivers\InCDfs.sys – (InCDfs)
DRV - [2008/05/20 15:34:56 | 000,009,728 | —- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\plturbh.sys – (PLTurbh)
DRV - [2006/11/02 08:27:36 | 000,020,112 | —- | M] (Dritek System Inc.) [Kernel | System | Running] – C:\Program Files\Launch Manager\DPortIO.sys – (DritekPortIO)
DRV - [2006/01/04 02:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.com/accounts/ServiceLogi…mp;ltmplcache=2
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=ie7&…1I7ACAW_enUS340
IE - HKCU\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" =
http://127.0.0.1:4664/search&s;=t-kdbOg…q={searchTerms}
IE - HKCU\..\SearchScopes\{B119812D-2A38-48DC-927D-4CBF4F4773B6}: "URL" = http://search.yahoo.com/search?fr=mcafee&p;={SearchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.startup.homepage: "
https://www.google.com/accounts/ServiceLogin?service=mail&passive;=true&rm;=false&continue;=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv;=zpwhtygjntrz&scc;=1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}:6.0.27
FF - prefs.js..extensions.enabledItems: [removed]:7.0.1466
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Family\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Family\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012/08/03 13:53:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012/09/08 09:14:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/02 21:36:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/07/03 20:05:08 | 000,000,000 | —D | M]
[2009/08/18 12:02:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Family\Application Data\Mozilla\Extensions
[2012/12/17 20:43:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\s9xmjwn0.default\extensions
[2012/12/17 20:35:02 | 000,000,000 | —D | M] ("Shopping Sidekick Plugin") – C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\s9xmjwn0.default\extensions\[removed]
[2012/12/17 20:35:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\s9xmjwn0.default\extensions\[removed]\chrome\content\extensionCode
[2012/09/08 12:36:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/28 13:20:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/27 17:23:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/03/12 18:13:37 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/08/16 11:05:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/09/15 14:41:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2012/09/08 09:14:47 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2009/09/01 18:19:43 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2009/09/08 14:55:06 | 000,027,976 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\atgpcdec.dll
[2009/09/08 14:55:07 | 000,126,360 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\atgpcext.dll
[2009/09/08 15:04:04 | 000,098,712 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
[2009/09/08 14:53:14 | 000,060,824 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\npatgpc.dll
[2009/08/31 23:30:17 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\mozilla firefox\plugins\npPandoWebInst.dll
========== Chrome ==========
CHR - homepage:
http://www.gmail.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
http://www.gmail.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: ActiveTouch General Plugin Container (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Pando Web Installer (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: npFFApi (Enabled) = C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AT_ChuckAnderson = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gegkoiakifeoejnjkbnnojkkdoegeofp\3\
CHR - Extension: avast! WebRep = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\
CHR - Extension: Gmail = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/09/26 11:17:08 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Shopping Sidekick Plugin) - {11111111-1111-1111-1111-110211181102} - C:\Program Files\Shopping Sidekick Plugin\Shopping Sidekick Plugin.dll (215 Apps)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\Nero\Nero8\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt File not found
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Prolific2571_OneButton] C:\Program Files\Prolific\EZ-DUB Finder\OneBtn.exe (Prolific)
O4 - HKLM..\Run: [SecurDisc] C:\Program Files\Nero\Nero8\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} http://simcity.ea.com/play/classic/SimCityX.cab (SimCityX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60A2B8E2-6C55-4D25-87B8-FC158D9E0D39}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D78F2BA9-07B8-4E35-865C-13DD4759FA65}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Family\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Family\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/12 00:07:49 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
System Restore Service not available.
========== Files/Folders - Created Within 30 Days ==========
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/11 14:20:47 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/02/11 14:20:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/02/11 14:20:33 | 1063,198,720 | -HS- | M] () – C:\hiberfil.sys
[2013/01/30 10:40:12 | 000,000,024 | —- | M] () – C:\Documents and Settings\Family\random.dat
[2013/01/30 10:38:55 | 000,000,023 | —- | M] () – C:\Documents and Settings\Family\jagexappletviewer.preferences
[2013/01/30 10:36:09 | 000,000,062 | —- | M] () – C:\Documents and Settings\Family\jagex_cl_runescape_LIVE.dat
[2013/01/19 14:48:33 | 000,139,264 | —- | M] () – C:\Documents and Settings\Family\Desktop\SystemLook.exe
[2013/01/19 14:48:00 | 000,053,826 | —- | M] () – C:\Documents and Settings\Family\Desktop\screenshot.GIF
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/01/19 14:48:39 | 000,139,264 | —- | C] () – C:\Documents and Settings\Family\Desktop\SystemLook.exe
[2013/01/19 14:47:57 | 000,053,826 | —- | C] () – C:\Documents and Settings\Family\Desktop\screenshot.GIF
[2012/09/26 10:59:28 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/09/26 10:59:28 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/09/26 10:59:28 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/09/26 10:59:28 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/09/26 10:59:28 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/07/03 19:48:56 | 000,000,067 | —- | C] () – C:\Documents and Settings\Family\jagex_cl_runescape_LIVE_BETA.dat
[2012/05/10 09:13:49 | 000,000,063 | —- | C] () – C:\Documents and Settings\Family\jagex_cl_runescape_LIVE1.dat
[2012/05/09 21:36:21 | 000,223,080 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/03/10 16:01:20 | 000,000,024 | —- | C] () – C:\Documents and Settings\Family\random.dat
[2012/03/08 20:33:16 | 000,016,410 | —- | C] () – C:\Documents and Settings\Family\.recently-used.xbel
[2012/02/18 09:02:19 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/10/29 15:23:40 | 000,000,062 | —- | C] () – C:\Documents and Settings\Family\jagex_cl_runescape_LIVE.dat
[2011/03/13 22:44:49 | 000,000,023 | —- | C] () – C:\Documents and Settings\Family\jagexappletviewer.preferences
[2010/03/26 19:49:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\Family\jagex__preferences3.dat
[2009/12/24 01:04:41 | 000,000,022 | —- | C] () – C:\Program Files\Sims2Pack Clean Installer.ini
[2009/10/09 12:19:16 | 000,014,336 | —- | C] () – C:\Documents and Settings\Family\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/02 17:23:59 | 000,000,129 | —- | C] () – C:\Documents and Settings\Family\jagex_runescape_preferences2.dat
[2009/08/30 10:48:20 | 000,000,140 | —- | C] () – C:\Documents and Settings\Family\Application Data\default.pls
[2009/08/27 11:20:11 | 000,001,024 | —- | C] () – C:\Documents and Settings\Family\.rnd
[2009/08/14 23:55:36 | 000,000,069 | —- | C] () – C:\Documents and Settings\Family\jagex_runescape_preferences.dat
========== ZeroAccess Check ==========
[2009/03/12 00:11:17 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
========== LOP Check ==========
[2009/03/12 01:06:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acer GameZone Console
[2010/11/25 18:06:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/09/08 17:23:29 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/11/09 12:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2011/11/13 21:43:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CheckPoint
[2010/09/20 13:51:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EA Core
[2010/09/20 13:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/03/12 01:31:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eSobi
[2010/05/26 21:09:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/09/08 15:53:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2009/08/31 23:31:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2009/09/08 15:52:56 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
[2009/03/12 01:32:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\Acer
[2009/03/12 01:06:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\Acer GameZone Console
[2012/08/03 13:58:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\CheckPoint
[2012/03/08 20:33:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\gtk-2.0
[2009/08/15 06:37:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\OpenOffice.org
[2012/07/03 20:05:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\Oracle
[2009/08/14 17:33:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\SulusGames
[2009/03/12 01:27:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\Super-Cow
[2010/08/25 12:30:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\SystemRequirementsLab
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/03/12 00:07:49 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/10/27 21:58:07 | 000,000,315 | —- | M] () – C:\Boot.bak
[2010/12/21 11:34:25 | 000,000,354 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2012/09/28 08:40:17 | 000,015,301 | —- | M] () – C:\ComboFix.txt
[2009/03/12 00:07:49 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2013/02/11 14:20:33 | 1063,198,720 | -HS- | M] () – C:\hiberfil.sys
[2009/03/12 00:07:49 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/25 09:26:34 | 000,009,456 | —- | M] () – C:\JavaRa.log
[2009/02/18 04:26:30 | 000,002,016 | —- | M] () – C:\MOD01SET0J00P2000K.enc
[2008/08/06 20:16:21 | 000,002,488 | —- | M] () – C:\MOD01WOS02ENP20001.enc
[2009/03/12 00:07:49 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 07:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/02/11 14:20:31 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2009/03/12 00:57:01 | 000,001,883 | —- | M] () – C:\RHDSetup.log
[2009/06/07 04:50:19 | 000,000,190 | —- | M] () – C:\Setup.log
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/03/12 00:07:26 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/10/22 00:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD97.DLL
[2007/10/22 00:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP97.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 21:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/08/21 04:12:33 | 000,041,224 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2008/12/05 00:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/12/24 01:04:41 | 000,000,022 | —- | M] () – C:\Program Files\Sims2Pack Clean Installer.ini
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/03/11 16:02:31 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/03/11 16:02:31 | 001,064,960 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/03/11 16:02:31 | 000,901,120 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2009/03/12 00:07:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2009/09/08 15:52:19 | 000,001,950 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Linksys EasyLink Advisor.lnk
[2009/08/23 15:15:13 | 000,001,611 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2009/03/12 00:07:50 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2009/03/12 00:07:50 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
[2010/06/19 15:43:36 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Family\Desktop\ATF_Cleaner.exe
[2013/01/19 14:48:33 | 000,139,264 | —- | M] () – C:\Documents and Settings\Family\Desktop\SystemLook.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2003/09/22 16:36:46 | 000,013,448 | —- | M] () – C:\WINDOWS\M3000Twn.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-09-22 22:37:27
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Option /s >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot /s >
"AlternateShell" = cmd.exe – [2008/04/14 07:00:00 | 000,389,120 | —- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
"" = FSFilter System Recovery
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
"" = Universal Serial Bus controllers
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
"" = CD-ROM Drive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
"" = DiskDrive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
"" = Standard floppy disk controller
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
"" = Hdc
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
"" = Keyboard
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
"" = Mouse
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
"" = PCMCIA Adapters
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
"" = SCSIAdapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
"" = System
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
"" = Floppy disk drive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
"" = Volume
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
"" = Human Interface Devices
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmadmin]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmboot.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmio.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmload.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmserver]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ip6fw.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NtLmSsp]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpcdd.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpdd.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpwd.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sr.sys]
"" = FSFilter System Recovery
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SRService]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdpipe.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdtcp.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\termservice]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WZCSVC]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
"" = Universal Serial Bus controllers
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
"" = CD-ROM Drive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
"" = DiskDrive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
"" = Standard floppy disk controller
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
"" = Hdc
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
"" = Keyboard
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
"" = Mouse
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
"" = Net – [2008/04/14 07:00:00 | 000,042,496 | —- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
"" = NetClient
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
"" = NetService
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
"" = NetTrans
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
"" = PCMCIA Adapters
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
"" = SCSIAdapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
"" = System
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
"" = Floppy disk drive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
"" = Volume
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
"" = Human Interface Devices
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment|SAFEBOOT_OPTION /rs >
< MD5 for: EXPLORER.EX_ >
[2008/04/14 07:00:00 | 000,356,615 | —- | M] () MD5=D7B59A7EC9CB1429FDCEC84A22228555 – C:\i386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2008/04/14 07:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 07:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/29 10:42:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\explorer.exe
< MD5 for: EXPLORER.SC_ >
[2008/04/14 07:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2008/04/14 07:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CH_ >
[2008/04/14 07:00:00 | 000,199,077 | —- | M] () MD5=1D662719AB9BB40BA7526B3973D3F626 – C:\i386\IEXPLORE.CH_
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2008/04/14 07:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 11:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EX_ >
[2008/04/14 07:00:00 | 000,037,887 | —- | M] () MD5=2B46169148FFD81CAE84572CD32BDF86 – C:\i386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2009/06/29 02:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2009/08/27 00:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2009/06/29 03:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2009/10/28 01:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 08:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie8\iexplore.exe
[2008/04/14 07:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2009/10/28 01:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2012/07/03 12:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ERDNT\cache\iexplore.exe
[2009/12/18 02:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/08/13 21:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2009/08/27 00:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
[2008/04/29 10:42:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 21:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui
< MD5 for: IEXPLORE.HL_ >
[2008/04/14 07:00:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\i386\IEXPLORE.HL_
< MD5 for: IEXPLORE.HLP >
[2008/04/14 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: WINLOGON.EX_ >
[2008/04/14 07:00:00 | 000,265,069 | —- | M] () MD5=063EF1A46C58A731F78AE5AF47070D65 – C:\i386\WINLOGON.EX_
< MD5 for: WINLOGON.EXE >
[2012/07/03 12:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
[2008/07/01 08:17:12 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\winlogon.exe
< End of report >